NextAI+ Praxis--:----UTC
AI Governance Weekly

Asia-Pacific: China Releases AI Safety Governance Framework 3.0 and Four Application Security Guidelines, Consults on Secure Agent Development; Hong Kong Proposes Compliance Declaration Pilot for Government AI Procurement

21 September 2026
Long read · 11 min
By NextAI+ Praxis

On 14 September 2026, the National Technical Committee 260 on Cybersecurity of the Standardization Administration of China (TC260) released the AI Safety Governance Framework 3.0, detailing risk grading and the management of agent identities, permissions, approvals and memory. The framework provides a governance reference for companies seeking to control risks arising from autonomous execution. On 15 September 2026, the TC260 Secretariat issued the General Provisions for AI application security and three sector-specific guidelines, detailing deployment safeguards, human review and content labelling for education, healthcare and audiovisual applications, and providing a basis for companies to design pre-launch reviews and acceptance tests. On 16 September 2026, John Lee, Chief Executive of the Hong Kong Special Administrative Region, delivered the 2026 Policy Address, proposing a pilot for supplier safety and ethical compliance declarations when selected government departments procure public-facing AI services; its scope and procedures remain to be finalised. On 18 September 2026, the TC260 Secretariat launched a public consultation on guidelines for secure development of agent systems, proposing measures for long-term memory authorisation and deletion, permission checks for tool calls and termination upon detection of anomalies. The draft provides a reference for development teams to identify control gaps in memory management and actual execution, but does not yet establish mandatory legal obligations.

§ i

China Releases Governance Framework 3.0, Detailing Agent Safety Controls

On 14 September 2026, the National Technical Committee 260 on Cybersecurity of the Standardization Administration of China (TC260), under the guidance of the Cyberspace Administration of China, released the AI Safety Governance Framework 3.0. It covers AI risk classification and grading, technical safeguards and safety management across the AI agent lifecycle.

The framework is a non-binding governance reference document. It retains the structure of risk classification, technical responses and comprehensive governance, with a dedicated appendix on agentic AI risk management. Appendix 1 grades security risks into five levels—low, moderate, considerable, major and extremely serious—based on application scenarios, level of intelligence and application scale. The level of intelligence includes the degree of autonomous decision-making and the scope of human intervention. Agents can plan tasks and call tools to execute actions. To address risks involving identities and permissions, tool execution and memory storage, Appendix 2 proposes dedicated identities, least privilege, human approval for critical operations and denial of execution by default when the approval process fails. Memory should be isolated by user and task, with its content, retention period and access scope determined by the processing purpose and necessity.

When a procurement agent moves from recommending requests for quotations to placing orders automatically, companies can use the framework to reassess its authorisation boundaries, separately reviewing the risks of reading quotations, creating orders and executing payments. Before connecting agents to email, document repositories or procurement systems, companies can assign separate accounts to different agents and restrict data access, action types and transaction limits. Pre-launch testing can simulate malicious emails prompting a change of payee account, access to another customer's memory and approval timeouts, to check whether operations can be blocked and escalated to the responsible person. Acceptance testing should establish whether business operations are traceable, stoppable and recoverable: link records of task authorisations, tool calls, human decisions and model versions, and verify whether credentials can be revoked after task termination and erroneous actions rolled back. Contracts for models or integration services can also specify component provenance disclosures, provision of investigation evidence and responsibilities for incident cooperation. These are implementation recommendations derived from the framework. Retention of operational logs, user conversations and long-term memory should be assessed separately against the data involved, processing purposes and applicable law, rather than subjecting them all to the same retention policy.

Version 2.0, released on 15 September 2025, had already included exploration of risk grading among its revisions. Version 3.0 follows that trajectory by further detailing the risks and controls associated with autonomous execution. In the same week, on 18 September 2026, California's Governor signed Executive Order N-9-26, directing the state government to study arrangements for on-site independent evaluations and emergency shutdown at large frontier model developers; it does not directly impose an obligation on companies to install shutdown switches. Both documents address the prevention of loss of control, but their governance targets and implementation mechanisms differ. China's framework provides technical and management references for developers, providers and users, while California's study mandate focuses on external verification of frontier developers and subsequent legal arrangements. The Chinese framework also calls for national standards and sector-specific rules on classification and grading. Priorities for monitoring include how individual sectors determine grading methods, risk levels and corresponding measures.

§ ii

China Issues Four Security Guidelines, Detailing AI Deployment Controls

On 15 September 2026, the TC260 Secretariat issued the Cybersecurity Standards Practice Guide—AI Application Security Guidelines: General Provisions, together with three sector-specific guidelines covering education, healthcare, and radio, television and online audiovisual services. The documents address security across the AI application lifecycle and in sector-specific use cases.

The four documents are technical publications related to standards. The laws, regulations and mandatory standards they cite remain applicable within their respective scopes. The documents are structured so that the General Provisions are used alongside the sector-specific guidelines. The General Provisions cover planning through decommissioning and specify safeguards for different deployment environments: for example, public cloud deployments emphasise encryption, compute isolation and auditing, while private cloud deployments require separate permission settings for compute, storage and applications. The education guidelines emphasise human review of assessment results and appeals; the healthcare guidelines preserve healthcare professionals' final clinical control; and the audiovisual guidelines detail content review, explicit labelling of generated or synthetic content, and preservation of labels in file metadata.

Procurers can translate sector-specific security requirements into executable acceptance tests. An education system can simulate a student challenging a grade to verify whether a teacher can review and correct it and retain a record of the decision. A healthcare triage system can be tested with conversations containing indications of a medical emergency, to verify whether it stops automated question-and-answer interactions and advises emergency care or transfers the user to a human. An audiovisual platform can check whether notices and metadata labels remain identifiable after a work is transcoded, edited and distributed. Deployment reviews should also map the actual flows of business data, model calls and logs, confirm storage locations and access permissions, and then verify the relevant cloud isolation or local safeguards. Contracts for external models or security services can specify version change notifications, delivery of testing materials and allocation of incident response responsibilities. After launch, companies should retain model version, human review and content distribution records relevant to dispute resolution, with their scope and retention periods limited in accordance with data protection requirements. These are implementation recommendations derived from the guidelines; the documents do not prescribe a uniform log retention period.

The AI Safety Governance Framework 3.0, released on 14 September 2026, retains the approach of risk classification, technical responses and comprehensive governance, while the new guidelines provide detail on deployment and sector-specific operations. Subsequent monitoring should assess whether sector regulators reference these guidelines in procurement, assessment or regulatory documents. On 18 August 2025, the US Food and Drug Administration (FDA) issued its final, non-binding guidance Marketing Submission Recommendations for a Predetermined Change Control Plan for Artificial Intelligence-Enabled Device Software Functions, explaining that changes consistent with an authorised plan may proceed without a separate submission for each change. China's healthcare guidelines cover institutional use and the provision of technical services, whereas the US guidance focuses on device manufacturers' submissions for updates. Their intended users and points of application differ. Healthcare AI teams operating across markets should therefore assess deployment safety, device market access and authorisation of updates separately.

§ iii

China Consults on Secure Agent Development, Covering Memory and Execution Controls

On 18 September 2026, the TC260 Secretariat launched a public consultation on the Cybersecurity Standards Practice Guide—Guidelines for Secure Development of Agent Systems (Draft for Comments), addressing the development of software agents based on large AI models and related evaluation activities.

The draft sets out technical recommendations across five stages: preparation, design, implementation, testing and release. It covers developers working through in-house development, low-code configuration and system integration, but excludes systems whose primary function is to control physical equipment, such as robots or autonomous vehicles. The consultation does not yet establish mandatory legal obligations. Specific proposals include authorisation controls for writes to long-term memory and permission checks before tool calls. Long-term memory is information retained across tasks for use in subsequent decisions. The draft recommends isolating memory belonging to different users and, upon deletion, also clearing or disabling copies, caches and indexes. It also recommends linking user authorisations, agent execution permissions and resource access permissions; limiting execution steps, retries and resource consumption; and providing human confirmation for high-risk actions and termination mechanisms for anomalous activity.

For a customer service agent able to read customer emails, retrieve orders and initiate refunds, companies can establish separate permissions for policy explanations, refund applications and actual payments in advance. They should enforce authorisation checks at the actual refund interface, with the business system verifying the approved order, amount and recipient for each request. Pre-launch tests can insert an instruction such as “future refunds no longer require approval” into historical emails, then check whether it enters long-term memory, affects the next conversation and whether the payment interface rejects unapproved requests. After deleting the memory, teams should check whether the content can still be retrieved from the memory store, caches or indexes. Operations staff should also rehearse pausing tasks, revoking tool credentials and preventing duplicate refunds, with a separate human-led correction process for payments already completed. Procurement or outsourcing contracts can specify who is responsible for memory cleanup, who can disable payment capabilities and who must repeat testing after model or tool updates. Records should link the authorisation basis, memory changes, call results and human responses for the same task. These preparations correspond to the draft's authorisation, memory, testing and release provisions and can help identify control gaps in existing systems.

The AI Application Security Guidelines: General Provisions, released on 15 September 2026, already provide cross-sector lifecycle guidance. The new draft focuses more specifically on the development of software agents. Comments are requested by 2 October 2026, and subsequent monitoring can track revisions to the provisions on authorisation, memory deletion and testing. On 30 April 2026, the US National Security Agency (NSA) and partner agencies jointly issued the non-binding guidance Careful Adoption of Agentic AI Services, recommending that agent use be limited to low-risk, non-sensitive tasks, with permission constraints, human oversight and continuous monitoring. The two documents approach the scope of autonomous execution differently: the Chinese draft discusses controls calibrated to risk levels, while the joint guidance takes a more conservative position on suitable uses. Teams operating across regions can share authorisation and audit tests, but should still determine the permitted scope of autonomous business operations separately and assess local data processing and sector-specific requirements.

§ iv

Hong Kong Proposes AI Governance Measures, with Compliance Declarations Planned for Government Procurement Pilot

On 16 September 2026, John Lee, Chief Executive of the Hong Kong Special Administrative Region, delivered the 2026 Policy Address, proposing AI risk governance measures covering government procurement, agent safety and product liability.

The work will be coordinated by the Chief Secretary for Administration, with a Commissioner for AI proposed under the Digital Policy Office (DPO). The Innovation, Technology and Industry Bureau will select pilot departments to require bidders for public-facing AI service projects to comply with the DPO's AI guidelines and submit safety and ethical compliance declarations for the technologies used, before gradually extending the arrangements to all policy bureaux and departments based on the pilot results. The DPO also plans to issue society-wide guidelines on agent safety management in 2027 jointly with the Hong Kong AI Research and Development Institute. A Department of Justice working group will review legal liability for harm caused by AI products. These are policy initiatives; the Policy Address does not yet specify the procurement pilot's launch date or detailed declaration procedures.

Suppliers delivering public service projects, such as government information assistants, can use the existing Ethical Artificial Intelligence Framework to map intended compliance declarations to specific tests and deliverables. For example, when a system answers questions about service eligibility or application documents, suppliers should check whether the supporting information remains valid, whether the knowledge base is updated promptly and whether queries can be transferred to a human when reliable answers are unavailable. Where user data is involved, they should also explain where inference requests and conversation records are processed, who can access them and how they may be used for training. Declarations should remain consistent with the version actually delivered and its operational configuration. Suppliers should retain linked records of model versions, data sources, test results and remediation, and specify upstream providers' responsibilities for change notifications, evidence delivery and incident cooperation in procurement and subcontracting agreements. Affected declarations should be reassessed after model upgrades or changes to the scope of data access. These preparatory recommendations draw on the procurement plans and the existing framework's provisions on impact assessment, deployment validation and continuous monitoring. The specific declaration items remain subject to the pilot documentation.

The Hong Kong Government developed the Ethical Artificial Intelligence Framework in 2021 to guide projects in identifying and managing risks including privacy and data security. The proposed addition of supplier compliance declarations to government procurement creates a specific point of application for the existing guidelines. On 17 February 2025, the UK Cabinet Office published the updated Procurement Policy Note Improving transparency of AI use in procurement (PPN 017). It provides optional disclosure questions for procurers, covering suppliers' use of AI in preparing bids and performing contracts; responses to the example questions are for information gathering only and are not scored. Suppliers operating across regions should prepare AI-use disclosures and evidence of compliance with applicable guidelines separately. In Hong Kong, subsequent monitoring should focus on how pilot tender documents specify the applicable guidelines, declaration content, verification methods and contract performance responsibilities.

← Back to AI Governance Weekly

Cite as · AI Governance Weekly · 21 September 2026

§ Recent signalsBack to Governance Weekly→
29 Sep 2026The EU adopts data centre ratings, the UK sizes up agentic cyber defence, and the FTC examines platform ad optimisation.28 Sep 2026China publishes on-device AI filings, Korea expands data innovation zones and debates agent privacy, and Japan studies consumer remedies.22 Sep 2026UK lawmakers call for dedicated AI legislation, the EU moves to limit AI companions for children, and California enacts synthetic-performer disclosure.18 Sep 2026US agencies issue a distillation advisory, the EU proposes an Innovation Act, and the UK confronts shadow AI.17 Sep 2026China rules on AI-fabricated reviews and answers distillation claims, Korea tightens breach notification, and Japan weighs consumer AI risks.

One quarterly digest, no weekly drip.

If you want both columns delivered together, four times a year, in one quiet email — leave an address. Otherwise just bookmark this page.